Hi, We have deployed ASA 5505 in our production network and using 1 MB dedicated ISP line and now going to upgrade 6 MB. As I think that Cisco ASA doesn't support IPS feature so I would know is there any problem we can face in future as per security concerned. All other models of ASA has IPS feature but through Cisco ASA 5505, is it possible that our organisation network not fully secured. Please suggest...Thnaks
In this case it is difficult to say Yes or No.
Instead I would say yes, because there could be many vulnerabilities / exploits over SQL port which are not in my knowledge or may be the experts. Everyday lots of new vulnerabilities are being discovered, so you cannot be sure that you are 100% secure.
Considering your case you have only SQL port allowed from Web server to the DB server, now if the attacker has exploited a script (ASP/JSP) which connects to the DB, he can easily play with the data on your Db server and so on.
With ASA 5505, its not supported.
You can go for AIP module with ASA 5510 and above. Check this page for more details.